CVE-2025-23274

EUVD-2025-30974
NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted input image with dimensions that cause integer overflows in array index calculations. A successful exploit of this vulnerability may lead to denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.5 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.31%
Debian logo
Debian Releases
Debian Product
Codename
nvidia-cuda-toolkit
bookworm
no-dsa
bookworm/non-free
vulnerable
forky/non-free
vulnerable
sid/non-free
vulnerable
trixie
no-dsa
trixie/non-free
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nvidia-cuda-toolkit
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
resolute
ignored
xenial
ignored
libnvjpeg-13-1
jammy
dne
noble
dne
resolute
not-affected
libnvjpeg-13-2
jammy
dne
noble
dne
resolute
dne
libnvjpeg-13-3
jammy
dne
noble
dne
resolute
dne